<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LSVPN Tunnel Recovery in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-tunnel-recovery/m-p/160705#M52366</link>
    <description>&lt;P&gt;I've set up my first LSVPN deployment and everything has gone without a hitch. &amp;nbsp;The only issue I ran into, we were doing an upgrade of PAN-OS on the gateway and satellites. &amp;nbsp;Satellites all went fine, but my gateway bombed out (first time its happened to me). &amp;nbsp;We were in an HA pair, but I had duplicate IPs on the network once the passive box rebooted, but I could never communicate or pass traffic with the passive box. Once I got the bad actor off the network and replaced with an on-site spare and the environment back up and stable, the Satellites didn't reconnect. &amp;nbsp;It took upwards of 45 minutes to get them back online. &amp;nbsp;It appears once the tunnel goes down on the satellite there's no way to recover until the next portal or gateway check-in. &amp;nbsp;I was in process to manually reconnect the firewalls, but they came up while I was en route.&lt;BR /&gt;&lt;BR /&gt;So, I've read the tunnel monitor difference between IPSEC and LSVPN and looked over the LSVPN deployment guide, but I guess I'm missing how the satellites will recover if connectivity to the gateway is lost. &amp;nbsp;Currently, I don't have a tunnel monitor set up on the Gateway. &amp;nbsp;Should I change this monitor to the physical&amp;nbsp;IP of the gateway instead of letting the monitor default to the tunnel interface of the gateway? &amp;nbsp;Would this improve recovery time?&lt;BR /&gt;&lt;BR /&gt;Thanks for any help!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jun 2017 14:28:08 GMT</pubDate>
    <dc:creator>dan731028</dc:creator>
    <dc:date>2017-06-12T14:28:08Z</dc:date>
    <item>
      <title>LSVPN Tunnel Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-tunnel-recovery/m-p/160705#M52366</link>
      <description>&lt;P&gt;I've set up my first LSVPN deployment and everything has gone without a hitch. &amp;nbsp;The only issue I ran into, we were doing an upgrade of PAN-OS on the gateway and satellites. &amp;nbsp;Satellites all went fine, but my gateway bombed out (first time its happened to me). &amp;nbsp;We were in an HA pair, but I had duplicate IPs on the network once the passive box rebooted, but I could never communicate or pass traffic with the passive box. Once I got the bad actor off the network and replaced with an on-site spare and the environment back up and stable, the Satellites didn't reconnect. &amp;nbsp;It took upwards of 45 minutes to get them back online. &amp;nbsp;It appears once the tunnel goes down on the satellite there's no way to recover until the next portal or gateway check-in. &amp;nbsp;I was in process to manually reconnect the firewalls, but they came up while I was en route.&lt;BR /&gt;&lt;BR /&gt;So, I've read the tunnel monitor difference between IPSEC and LSVPN and looked over the LSVPN deployment guide, but I guess I'm missing how the satellites will recover if connectivity to the gateway is lost. &amp;nbsp;Currently, I don't have a tunnel monitor set up on the Gateway. &amp;nbsp;Should I change this monitor to the physical&amp;nbsp;IP of the gateway instead of letting the monitor default to the tunnel interface of the gateway? &amp;nbsp;Would this improve recovery time?&lt;BR /&gt;&lt;BR /&gt;Thanks for any help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 14:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-tunnel-recovery/m-p/160705#M52366</guid>
      <dc:creator>dan731028</dc:creator>
      <dc:date>2017-06-12T14:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: LSVPN Tunnel Recovery</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-tunnel-recovery/m-p/160821#M52399</link>
      <description>&lt;P&gt;so there are 2 "is it dead methods"&lt;/P&gt;&lt;P&gt;DPD - on Phase 1&lt;/P&gt;&lt;P&gt;and&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tunnel Monitor - on phase 2&lt;/P&gt;&lt;P&gt;tunnel monitor does give you more troubleshooting allowances&lt;/P&gt;&lt;P&gt;(an IP address is assigned and 'pingable')&lt;/P&gt;&lt;P&gt;thus an actual packet traverses the tunnel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are you using static or dynamic routing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is passive setting enabled....checked?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 21:54:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lsvpn-tunnel-recovery/m-p/160821#M52399</guid>
      <dc:creator>DarinSutton</dc:creator>
      <dc:date>2017-06-12T21:54:53Z</dc:date>
    </item>
  </channel>
</rss>

